US2020053058A1PendingUtilityA1

Method and system for digital rights management of documents

Assignee: ENCRYPTICS LLCPriority: Sep 28, 2005Filed: Jun 19, 2019Published: Feb 13, 2020
Est. expirySep 28, 2025(expired)· nominal 20-yr term from priority
G06F 2221/2137H04L 63/0435H04L 63/061G06F 2221/2101H04L 9/3263H04L 9/3247H04L 9/0861G06F 21/10
64
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method and system for transmission of digital content via e-mail with point of use digital rights management is disclosed. The secured access rights to the digital content may be customized for individual recipients by the sender, and may evolve over time. The access rights are enforced according to a time-dependent scheme. A key server is used to arbitrate session keys for the encrypted content, eliminating the requirement to exchange public keys prior to transmission of the digital content. During the entire process of transmitting and receiving e-mail messages and documents, the exchange of cryptographic keys remains totally transparent to the users of the system, Additionally, electronic documents may be digitally signed with authentication of the signature.

Claims

exact text as granted — not AI-modified
1 - 15 . (canceled) 
     
     
         16 . A method for granting recipient access to a cryptocontainer, the cryptocontainer including an encrypted first section, an encrypted second section and an encrypted key portion, the method comprising, by a server computer:
 receiving, from a recipient of the cryptocontainer, the encrypted first section and the encrypted key portion;   wherein the encrypted first section includes a recipient list and a first symmetric key, and wherein the encrypted first section has been encrypted using a second symmetric key;   wherein the encrypted key portion comprises the second symmetric key, and wherein the encrypted key portion has been encrypted using a public key of the server computer;   responsive to the receiving, decrypting the recipient list and the first symmetric key from the encrypted first section;   responsive to a determination that the recipient matches at least one recipient entry in the recipient list:
 re-encrypting the first symmetric key using a public key associated with the recipient; and 
 sending the re-encrypted first symmetric key to the recipient of the cryptocontainer so that the recipient can decrypt the encrypted second section of the cryptocontainer. 
   
     
     
         17 . The method of  claim 16 , comprising, responsive to a determination that the recipient does not match any recipient entry in the recipient list, denying the recipient access to the encrypted second section of the cryptocontainer. 
     
     
         18 . The method of  claim 16 , comprising authenticating an address of the recipient via communication with an authentication server. 
     
     
         19 . The method of  claim 16 , comprising authenticating the recipient via receipt, from the recipient, of a certificate signed by a known authentication server. 
     
     
         20 . The method of  claim 16 , comprising determining that the recipient matches a recipient entry in the recipient list. 
     
     
         21 . The method of  claim 20 , wherein the determining comprises determining that the recipient is a member of a user group in the recipient list. 
     
     
         22 . The method of  claim 20 , wherein the determining comprises determining that the recipient list includes an address of the recipient. 
     
     
         23 . A server computer comprising a processor and memory, wherein the processor and the memory in combination are operable to perform a method for granting recipient access to a cryptocontainer, the cryptocontainer including an encrypted first section, an encrypted second section and an encrypted key portion, the method comprising:
 receiving, from a recipient of the cryptocontainer, the encrypted first section and the encrypted key portion;   wherein the encrypted first section includes a recipient list and a first symmetric key, and wherein the encrypted first section has been encrypted using a second symmetric key;   wherein the encrypted key portion comprises the second symmetric key, and wherein the encrypted key portion has been encrypted using a public key of the server computer;   responsive to the receiving, decrypting the recipient list and the first symmetric key from the encrypted first section;   responsive to a determination that the recipient matches at least one recipient entry in the recipient list:
 re-encrypting the first symmetric key using a public key associated with the recipient; and 
 sending the re-encrypted first symmetric key to the recipient of the cryptocontainer so that the recipient can decrypt the encrypted second section of the cryptocontainer. 
   
     
     
         24 . The server computer of  claim 23 , the method comprising, responsive to a determination that the recipient does not match any recipient entry in the recipient list, denying the recipient access to the encrypted second section of the cryptocontainer. 
     
     
         25 . The server computer of  claim 23 , the method comprising authenticating an address of the recipient via communication with an authentication server. 
     
     
         26 . The server computer of  claim 23 , the method comprising authenticating the recipient via receipt, from the recipient, of a certificate signed by a known authentication server. 
     
     
         27 . The server computer of  claim 23 , the method comprising determining that the recipient matches a recipient entry in the recipient list. 
     
     
         28 . The server computer of  claim 27 , wherein the determining comprises determining that the recipient is a member of a user group in the recipient list. 
     
     
         29 . The server computer of  claim 27 , wherein the determining comprises determining that the recipient list includes an address of the recipient. 
     
     
         30 . A computer-program product comprising a non-transitory computer-usable medium having computer-readable program code embodied therein, the computer-readable program code adapted to be executed to implement a method for granting recipient access to a cryptocontainer, the cryptocontainer including an encrypted first section, an encrypted second section and an encrypted key portion, the method comprising:
 receiving, from a recipient of the cryptocontainer, the encrypted first section and the encrypted key portion;   wherein the encrypted first section includes a recipient list and a first symmetric key, and wherein the encrypted first section has been encrypted using a second symmetric key;   wherein the encrypted key portion comprises the second symmetric key, and wherein the encrypted key portion has been encrypted using a public key of a server computer;   responsive to the receiving, decrypting the recipient list and the first symmetric key from the encrypted first section;   responsive to a determination that the recipient matches at least one recipient entry in the recipient list:
 re-encrypting the first symmetric key using a public key associated with the recipient; and 
 sending the re-encrypted first symmetric key to the recipient of the cryptocontainer so that the recipient can decrypt the encrypted second section of the cryptocontainer. 
   
     
     
         31 . The computer-program product of  claim 30 , the method comprising, responsive to a determination that the recipient does not match any recipient entry in the recipient list, denying the recipient access to the encrypted second section of the cryptocontainer. 
     
     
         32 . The computer-program product of  claim 30 , the method comprising authenticating an address of the recipient via communication with an authentication server. 
     
     
         33 . The computer-program product of  claim 30 , the method comprising authenticating the recipient via receipt, from the recipient, of a certificate signed by a known authentication server. 
     
     
         34 . The computer-program product of  claim 30 , the method comprising determining that the recipient matches a recipient entry in the recipient list. 
     
     
         35 . The computer-program product of  claim 34 , wherein the determining comprises determining that the recipient is a member of a user group in the recipient list.

Join the waitlist — get patent alerts

Track US2020053058A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.